So Apple have finally adopted NFC, huh?  Big deal, Samsung have partnered with Visa and MasterCard to promote NFC for over a year, and included NFC chips in their devices long before that.

Apple’s wallet provides you options to choose which credit card you want to use. CREDIT CARD?! REALLY?! How is that innovation in payments?! The whole point of mobile payments is that you don’t need a branded card to make a payment, at least it should be the point!

Payments has been, and will always be, just an exchange of stored value for a service or product whose value is, in turn, entirely arbitrary. e.g. I work for an entire week for a value I have agreed with my employer, and I am now going to buy a designer suit for the same ‘price’. The fact that the suit was made for a fraction of the ‘cost’ I paid for it is why its value is arbitrary; because regardless of the price, I agreed to it.

So what have Apple done differently? You can now authenticate the payment with your fingerprint. Seriously? People barely trust the fingerprint to log into their phones, let alone authenticate a payment. And seeing as the value of the contactless transaction is set below £20 (for the UK) and authentication is not required at ALL, why would you add an extra step?

I can tell you now that the credit card brands will not accept biometrics any time soon to replace EMV for higher transaction values when even software PIN (as opposed to hardware) is still rejected. Couple the fact that Apple’s global market share for phones is less than 12%, with the US being their only viable new market (who love their credit cards), and you have a completely empty offering.

But, you may say, Apple has 800 million iTunes users! Irrelevant, because there are nowhere near 800 million iPhones in use. From their initial inception way back in 2007, Apple sold their 500 millionth iPhones in June 2014. That’s total sales, all models, in seven years. Estimates suggest that there are less than 300 million in use globally, compared to a total of 1.75 billion smartphones.

On top of Apple’s minimal – and shrinking – market share, the transition of credit card payments to direct bank account payments through a mobile device has, through necessity, started small. Security is absolutely an issue, which is why the back-end wallets generally consist of credit cards, which handle the fraud / loss liability. With your bank account, it’s YOUR money, and the banks have yet to accept the liability for loss though mobile apps. When they do, the card brands will have no benefit and the transition to mobile will accelerate.

So why DON’T the banks provide this function themselves? Because they make money from credit cards, plain and simple, and it will be a tough sell to charge the fees they do now when accessing your own funds, even if they do provide a ‘fraud resistant’ service. Besides, the money from credit cards is not from the cards themselves, it’s on the interest you pay for your LINE of credit, so the poor banks can still make their squillions. That’s a relief.

Besides, people take their phones for granted, just as they do water coming out of the tap (I know, 1st world problems), and people simply do not see the issue with continuing to use plastic, so how will the mass adoption of mobile payments really take off? Simple; value-add services and guaranteed security.

Value-Add Services: Retailers are the only ones who can make this happen, not phone companies, not card brands, and certainly not the banks. For retailers to make the enormous investment required to change from a credit card infrastructure to mobile / hybrid there needs to be a clear positive effect on the bottom line. Unfortunately, with the ridiculous number of choices related to loyalty schemes, instant coupons, e-wallets and so on, no retailer knows which to back.

Guaranteed Security: The reason credit cards still eclipse mobile payments is because if you use a credit card you are not liable for fraud, the issuer is. The so-called liability shift. If you take out this middle-man, who accepts the risk? The retailers? The bank? The mobile app service providers? Someone has to, because you can be damned sure it won’t be the consumer.

Which brings us to only relevant thing to come out of Apple’s announcement; NFC is now the technology of choice. All we need now is the consolidation of every other service, someone to accept the inevitable losses, and mobile payments can come into its own.

Yeah. Right.

I don’t think anyone in the payments arena has any doubt that credit/debit cards, in their current form, will die over time in favour of mobile devices. It’s a natural next step to replace something ubiquitous with something even more ubiquitous.

So where does that leave the SSC, and the card schemes themselves for that matter?

You only have to look at Visa Europe’s website Visa Vision to see that they are moving towards mobile (and other innovations), and articles like The Revolution is Here, do not even mention EMV, and the only reference to plastic is in a future past-tense.

It also begs the question as to why the card schemes are pushing EMV when they themselves see an end to their reign-of-plastic. But the answer is obvious, the cost of fraud over the next 5 – 10 years far outweighs the cost of the transition. The US alone saw $7.1B in credit card fraud in 2013 (according to Business Insider), and I have estimated that the cost of EMV transition in the US is ‘only’ $12B (Why the US Will Not Adopt EMV (Chip & PIN), EMV in the US, a 12 BILLION Dollar Mistake).

So why am I so anti-EMV? Because there are technologies NOW that can replace it, are in more hands, and more widely distributed than cards ever were. Your mobile phones.

So back to my point; what WILL the cards brands and the SSC do once the plastic dies? Clearly the brands have an enormous leg-up on any new player in the cashless game, and have massive amounts of capital to invest in meeting every aspect of this [so-called] disruptive innovation; research on innovation, testing proofs-of-concept, garnering adoption within the finance community, and of course, rolling it out to end users.

Mobile phone companies made a small play, and missed, banks could have done it, and didn’t, and large retail could have had a huge impact, and haven’t. Probably because in these three case – even banks – payments is not a core function. Being PAID is core, making the payment is not, so only the card schemes have payments as their entire reason-to-be, and therefore the most motivation.

OK, so if we assume that the card schemes are going to make a huge play in every cashless payment innovation from this point forward, where does that leave the SSC? Probably in exactly the same place, with only one change in title; From Payment Card Industry Security Standards Council, to Payment Industry Security Standards Council.

Regardless of the form of payment there HAS to be a security standard around the protection of the data. Not that the current standards are anywhere near adequate, even for cardholder data, but the SSC has significant experience adopting and implementing standards globally. From mobile apps, to software PINs, to identity management (for KYC, AML etc.) to crypto-currencies, everyone developing technologies must adhere to a minimum set of protective baselines.

So am I really proposing, after so many less-than-positive blogs related to the PCI DSS and the SSC, that they be a standards body for every form of payment globally? Well, no, I’m not, but I think that if they don’t TRY to be just that (with the card brand’s backing), there is no-where else for them to go.

Despite my voluble criticisms of the card brands and the SSC alike, they ARE well placed to do good. I hope they take the opportunity now, because it won’t come again.

[If you liked this article, please share! Want more like it, subscribe!]

I read a rather long but very interesting article the other day (thank you nephew) titled ‘The Coming Digital Anarchy‘ by Matthew Sparkes (Telegraph). Despite the rather dramatic title (I have done this egregiously myself from time to time), the concept regarding the future of ‘blockchains’ is sound, and is a far better researched and a far more encompassing version of my earlier article ‘On The Irrelevance of Money‘.

However, with the exception of one fairly cryptic phrase; “In [his] version of the future, identity and reputation will be the new currency.” the means by which this new order will be usable has not been addressed. Nor have I seen it addressed in any other articles of its ilk.

Regardless of the manner in which our data is stored, either the current file/database method, or the de-centralised / distributed method of blockchains (written for the crypto currency Bitcoin, but has much wider implications), we, the owners of the data, need to access its function securely, and put it to use in any scenario we choose.

If you can assume for the sake of argument, that the concept of the block chain is a valid method of storing and securing data, how can we access the data’s benefits in a method that’s equally secure? Your computer, mobile phone, static knowledge (username / password etc.), physical tokens (credit cards, RSA Tokens) are what we use now, and seeing as they are based on current methods of authentication, inherit their flaws. It is a hard enough stretch to get people to accept that their entire ‘Internet Worth’ (trying to coin this phrase) is not maintained by any institution, but to grant access to this without ensuring your identity is protected in the same way goes too far, even for me.

Your identity is all you have that’s truly yours, everything else is a universally agreed representation of value (money for example), so until such times as we can bring our full identity to bear we are reliant on small, and very specific elements of it. Elements that are relatively easy to steal, and duplicate.

It follows therefore, that the more of our identity were can securely distribute, the harder it will be for anyone to pretend they are us. Even in a scenario like Invasion of the Body Snatchers where they completely take over our physical bodies, unless the entirely of my life was instantly at the impostor’s disposal, AND they were able to duplicate my personality precisely, my family and friends would know there was something wrong. And if I’m honest, might actually prefer the new me.

Which brings me to the true value of your identity; Trust. You would not lend a stranger a £1,000 without significant rules in place, but you would think nothing of lending it a family member (assuming they’re not a douche-bag). Why? Because you have a lifetime of trust built up behind you.

How then do we duplicate a lifetime of trust in an electronic form, between two complete strangers? Well, if you’re reading this YOU can’t, probably it’s too late for most of us, but it’s NOT too late for those young enough to begin the process. All we need is the technology.

Oddly enough, I think that block chains provide the answer here too, but I am making a huge assumption based on limited knowledge of how they work. However, from what I know already, they are an ideal medium as their very nature is to record everything that ever happens from the beginning. It just needs to be worked out how to accept the input from everyone with whom the individual comes into contact, and how to represent that in terms of levels of trust. Much like a credit rating, but infinitely more difficult to explain.

In just the last few days Ghash has thrown a huge spanner in the works by controlling the magic ‘51%’ of Bitcoin, thus completely ruining the whole concept of de-centralisation. They have said that we should not worry, and to trust them, but so do the banks. There is clearly a lot of work left to be done.

Until people MUCH smarter than me can work out these issues, and we completely redefine the concept of Privacy (that’s the easy part, right?), this is all theory and speculation, but I cannot see any safer way to get where we are headed. Things change, whether we are ready or not.

Your identity as a baseline is both irrefutable, and cannot be duplicated, but it DOES mean you have to be a decent citizen your whole life or be ostracised. Is that such a bad thing if we have a global consensus on right and wrong?

[If you liked this article, please share! Want more like it, subscribe!]

OK, so money isn’t irrelevant …yet, but it will be. Like so many things that are in existence, they are only still used because they have either achieved global ubiquity, or there is nothing better to replace them, or both.

Money, in all its forms, is probably the definitive example of this, but I can actually see a time in the not too distant future when it will be replaced with what it has always represented; Value.

Let me take a step back here and say that this subject is wayyy too complex for me to do true justice, and I have no intention of reading any books on economics to ensure it’s factually accurate, but by its very nature, money is limiting to the continuation of globalisation. Like it or not, the world is getting smaller and less unique across traditional borders both physical and political. People are starting to want the same things, and while not all of things they want are good, the common ground between them is once again driven by value.

Money simply cannot keep up with the changes, and the massive complexity of producing cash, providing debit and credit services, exchange rates, inflation, and a plethora of other things I have made it my goal to never understand, will eventually drive a requirement for something new;

I’m calling it ‘Digital Identity and Virtual Value Management’.

Errr, what?

Another step back; In the past, if you were a wheat farmer and needed meat, you would exchange wheat for meat at a ratio you agreed directly with the person standing right in front of you. You would then each go on your way happy that you have received fair value for your goods. However, if you wanted dairy products, carpentry skills, metal working skills or a whole host of services, you had to repeat this process, and of course, the representative values would always change depending on your immediate needs.

Now, in a massively over-simplification of history and probably fact, it was decided in the year [mumble-mumble] that it would make sense to replace the bartering system with a universally agreed (i.e. by the ‘government’) meaningless object (money), which would represent the VALUE of every commodity so that the holder of this meaningless object was owed the value of it in any commodity they chose.

Great, so now instead of carrying around huge quantities of wheat, our farmer can now walk up to any provider of goods and exchange their meaningless objects for whatever they want.

Eventually these meaningless objects became paper-based, then plastic, and now it’s digital, but it’s still meaningless. Only the VALUE of what it represents means anything, and you SHOULD be able to spend that any time, any place, anywhere, without the need for a meaningless object.

Your identity should replace the meaningless object, and your value should replace money in all it’s forms.

But who sets your value? Who is to say that the services of a lawyer are more valuable than those of a plumber?

You do.

Currently, if you accept £50,000 / year for your employment, YOU are the one who set that value, not your employer. If you think you’re worth more, go somewhere else, or, what you should do is increase your value by improving yourself in some way (education, experience, work harder, you name it). And herein lies one of the biggest mistakes people make their whole lives; focussing on money when what they SHOULD be focusing on is improving their own worth, their VALUE to others.

So, what is Digital Identity? It’s the unequivocal ability for you to prove that you are you, to anyone, anywhere. If everyone in the world KNEW that you were you, then you would not need money, passports, or any physical form of identity. Whether this is effected by biometrics and knowledge verification or [more likely] a combination of these and other yet-to-be invented factors is unclear, but the digitalisation of everything will continue until this form of Identity Management is commonplace.

And Virtual Value? This you can see happening already with Bitcoin and its brethren. What’s missing is the input of non-monetary value, or in other words, I have no way of entering my self-determined worth into a virtual environment, then have others validate it for my actual work in a way that I can spend on something else. But this is coming too, it almost has to.

I can imagine a time when I perform a piece of work for someone, immediately be ‘credited’ with the agreed virtual value, then be able to walk into a store, pick up what I want and walk out again without performing any manual payment transaction whatsoever. My Digital Identity will be confirmed the second I walk into the store, the value of the goods will be automatically calculated based on my choices, and the value of those good will be deducted from my virtual net-worth (or Internet-worth! :)) as soon as I step back out into the street.

Seems rather ridiculous that we still use credit cards, doesn’t it?

For those who don’t know what the Rosetta Stone is, it’s a tablet found in 1799 that greatly assisted the translation of ancient Egyptian Hieroglyphs [subsequently] to every modern language.

So why do I use this as an analogy for non-cash payments?

Hieroglyphs​ had puzzled scholars for centuries until the Rosetta Stone unlocked them enough for the translation to move forward to completion. Having a software PIN will effect the exact same unlocking of the transition of non-cash payments from plastic to mobile. We have had payment cards for 60+ years, with nothing in that time anywhere near ubiquitous enough to disrupt them​, now ​we do. And while mobile devices are in no way perfect, and in many ways even less secure than payment card, ​they ​​are​ already far more prevalent​. ​Despite all ​of mobiles’s flaws, they ​are being used ​today as a payment medium​, a trend that will continue until plastic is replaced completely (at least in its current form).​

Th​ere are too many reasons​ for the continuity​ to go into​ here​ (sheer functionality being the top one), but it has been slow because until now every mobile payment innovation was just a little too much for people to accept, just a smidge too radical to gain the necessary momentum.

This is probably because none of those innovations kept the most widely used of the authentication mechanisms in the world; the PIN. The enormously complex and expensive chip & PIN (EMV) used for credit cards is accepted globally (if they can afford it), but up till now there has been no way to effect an acceptable level of security on a device that is never going to be as secure as a system built for purpose.

But ‘as secure’ is not the point, ‘secure enough’ is. You’re not fighting for perfection and zero loss through theft, you’re fighting for making it too difficult for thieves to bother. This can only be effected by layers of security, the so-called defence-in-depth. EMV put all of its security controls into a single factor (they had no choice), but mobile devices have access to numerous – and ever expanding – options:

  1. Geolocation/Geofencing: Whatever you want to call it, and whatever buzz phrases vendors will come up with next, they all mean the same thing; are you where you should be? Should you be paying for something in Glasgow if you live in London? Maybe, but when you set the areas from which payments can be made, you are removing the majority of the bad guys’ ability to process a fraudulent transaction.
    Yes, there can be privacy issues, but most vendors have dealt with that now.
    o
  2. Device Authentication: Every mobile phone has a serial number, IMEI number, and other built in identifiers. If your device is registered it’s very difficult to use another device to get in the middle. Not impossible, just difficult.
    o
  3. Application Signing and Authentication: Minimal security in and of itself, but is another security layer which ensures as much as possible that only known good apps are used. Apple and Google have their own ways of doing this for downloads, neither of which is adequate. Ongoing application verification can be relatively useful though.
    o
  4. App Blacklisting / Malware Detection: Very early days yet for mobile devices, but in the same way that operating systems anti-virus vendors have made untold fortunes regurgitating known bad things into signatures, mobile devices will have the ability to blacklist apps that should never be running on devices secure enough to authenticate payments. OS hardening guides (SELinux for example) and version control (Android must be at v4.2 and above for example) are fundamental baselines.
    o
  5. PIN Image ‘Watermarking’: Most internet banking sites now have a facility whereby you can upload a personal image to ensure that your open communication is actually with your bank and not redirected to a bad guy. Mobile devices make this factor possible and can even be configured into the PIN pad image.
    o
  6. Encryption (Packet and Transport Layer): Obvious stuff, and relatively trivial to circumvent when you have access to the base operating system kernel (where all jailbreaks take place), but still a very valid concept, especially when you consider the very clever technology surrounding things like Secure Remote Password protocol (SRP).

​Even today there are more options than this, and even implementing all of them at once is seamless to the end user once they have registered their device​. Any one of these by itself is clearly inadequate, but can you really see a bad guy sitting in Starbucks cracking ALL of these in the few moment it takes you to pay for your coffee?

By their nature, mobile devices will always be insecure and limited (bloated OSs, battery life, delicacy, theft and so on) and cannot be seen as a long term solution in payments the way the credit cards were, but I don’t think anyone can deny that they will replace plastic. Mobile devices will take payments to places credit cards can never reach, and the functionality and distribution of payment innovation through mobile devices will grow exponentially over the next 5 – 10 years, it just needs something to help everyone make that transition;

The software PIN.

[If you liked this article, please share! Want more like it, subscribe!]